New PCPJack Worm Targets Docker, Kubernetes, Redis, and MongoDB for Credential Theft
ID: e05efb6d-0a81-5de8-990b-c0517eca4756
STIX ID: report--e05efb6d-0a81-5de8-990b-c0517eca4756
Feed Name: cybersecurityNews.com
PCPJack is a sophisticated cloud-targeting worm and credential stealer that scans Common Crawl hostnames to discover exposed Docker, Kubernetes, Redis, MongoDB and other services, exploits multiple public CVEs to gain access, harvests SSH keys, API tokens, database credentials and wallet files, encrypts exfiltrated data with X25519/ChaCha20-Poly1305 and sends it via Telegram, and deploys multi-architecture Sliver backdoors for persistence; the report from SentinelOne includes detailed technical analysis, IoCs, and recommended mitigations such as enforcing MFA and securing container and cloud APIs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
